Re: [Multiformats] Multiformats Considered Harmful

"Martin J. Dürst" <duerst@it.aoyama.ac.jp> Mon, 11 September 2023 04:54 UTC

Return-Path: <duerst@it.aoyama.ac.jp>
X-Original-To: multiformats@ietfa.amsl.com
Delivered-To: multiformats@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id E7732C14CF15 for <multiformats@ietfa.amsl.com>; Sun, 10 Sep 2023 21:54:31 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -7
X-Spam-Level:
X-Spam-Status: No, score=-7 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, NICE_REPLY_A=-0.091, RCVD_IN_DNSWL_HI=-5, RCVD_IN_MSPIKE_H2=-0.001, RCVD_IN_ZEN_BLOCKED_OPENDNS=0.001, SPF_PASS=-0.001, T_SCC_BODY_TEXT_LINE=-0.01, URIBL_DBL_BLOCKED_OPENDNS=0.001, URIBL_ZEN_BLOCKED_OPENDNS=0.001] autolearn=ham autolearn_force=no
Authentication-Results: ietfa.amsl.com (amavisd-new); dkim=pass (1024-bit key) header.d=itaoyama.onmicrosoft.com
Received: from mail.ietf.org ([50.223.129.194]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tl0bdGIRyRWf for <multiformats@ietfa.amsl.com>; Sun, 10 Sep 2023 21:54:28 -0700 (PDT)
Received: from JPN01-TYC-obe.outbound.protection.outlook.com (mail-tycjpn01on2110.outbound.protection.outlook.com [40.107.114.110]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 1EA72C14CF13 for <multiformats@ietf.org>; Sun, 10 Sep 2023 21:54:27 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=NmovfcEQCAs/b/zW0zLifwP36H4y17K1GDb1EpOxX6TIS7xpY0P4lWhiwTnivCCSXASIoA33RRNaHkuowE4mB8iF5fFTAOP9WBY88JN07Xn4iF3+EEpsoyNNBjWewDWYNoMBYzHzMBS24zYfhYUVn9v0/0pe4ClkZPfXMr4Z6yqvLBpt5LT7xGbVnoWdxe9bHd6UCKCU6oyJgZmPeTEUrV9QfPX+Yp+DDW5ibOw5lBEYnXasyby+DmpKE8gUbcCdK3KbjNj+9kPRG55ZvtAvCBv9jo9aCIaege02z/gsqP5psC3QK25Rd7u+VyXvPzg/AaMdWffHOWohWM7E7V2oCA==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=44Vhbw3qQ/TyMWyItU2280HJBiJm5gatnStd51yVdFI=; b=jgF3GxaUsQT9bx7BfugN6IhnQ3lVzB+2ba+riJDrUhxT6lh6zY2aQtn/vdLtF8FkWSpO8AmEPB1xBnbAdRqOyBsFHUcZEgRulHEPBWTCMd9/oDVLSzPASo2FJQwlNby70KKMMqZvodk3tI/l+1ih1fJ4AjGiVEPvPLySzApHUUII0oos0b6QbjECLpvnVUgP95QddN+fBysFqn4tyI5SdhDPWJq427gKqmEEEI90abNnzB23cwaj2C2hG2O/5wV0FFa94e0szkWhs1IMuLj130IGeGqyDX/8iw/ywYRqsFGODh2gs2+opVPipgMfbvSpwuanN/xnSGOL3H8ViD+qqA==
ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=it.aoyama.ac.jp; dmarc=pass action=none header.from=it.aoyama.ac.jp; dkim=pass header.d=it.aoyama.ac.jp; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=itaoyama.onmicrosoft.com; s=selector2-itaoyama-onmicrosoft-com; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-SenderADCheck; bh=44Vhbw3qQ/TyMWyItU2280HJBiJm5gatnStd51yVdFI=; b=rB5Vyrno9Cn6rwzCrdeQls/wocQSnjzXOiVy6Kt+vwFhj+vah7zWMW5Q3g2Qo0XNeU58urNj5nZR9i+z9HwcyELF0Iym7HxXmdiEaORueW+Kc8+pKHdXPTU89NNOycDotjV3wHtme+VGrpoi5G/pAhlRIyCO4ha9OHYJFkit+s4=
Authentication-Results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=it.aoyama.ac.jp;
Received: from TYAPR01MB5689.jpnprd01.prod.outlook.com (2603:1096:404:8053::7) by TYWPR01MB9510.jpnprd01.prod.outlook.com (2603:1096:400:1a7::13) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.6768.35; Mon, 11 Sep 2023 04:54:25 +0000
Received: from TYAPR01MB5689.jpnprd01.prod.outlook.com ([fe80::d4a2:6f19:ba9f:ed7a]) by TYAPR01MB5689.jpnprd01.prod.outlook.com ([fe80::d4a2:6f19:ba9f:ed7a%7]) with mapi id 15.20.6768.029; Mon, 11 Sep 2023 04:54:25 +0000
Message-ID: <b6409205-1ad2-a163-e14c-336e799005ad@it.aoyama.ac.jp>
Date: Mon, 11 Sep 2023 13:54:25 +0900
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101 Thunderbird/102.15.0
Content-Language: en-US
To: Michael Jones <michael_b_jones@hotmail.com>, Orie Steele <orie@transmute.industries>, Carsten Bormann <cabo@tzi.org>
Cc: "multiformats@ietf.org" <multiformats@ietf.org>, Murray Kucherawy <superuser@gmail.com>, Barry Leiba <barryleiba@computer.org>, Francesca Palombini <francesca.palombini@ericsson.com>, Roman Danyliw <rdd@cert.org>, Paul Wouters <paul.wouters@aiven.io>, Russ Housley <housley@vigilsec.com>, Henk Birkholz <henk.birkholz@sit.fraunhofer.de>, Richard Barnes <rlb@ipv.sx>
References: <F814189D-031F-4CED-AC9A-F6049D010632@tzi.org> <81D17EDC-723D-4977-AA82-6164DDB5B431@tzi.org> <CAN8C-_LpYSimtHTn0nE7HN13iJ8FyxchaDm4G1mTX97MhYf=bw@mail.gmail.com> <MW4PR02MB7428BE7784A204FC9F945685B7EFA@MW4PR02MB7428.namprd02.prod.outlook.com>
From: "Martin J. Dürst" <duerst@it.aoyama.ac.jp>
Organization: Aoyama Gakuin University
In-Reply-To: <MW4PR02MB7428BE7784A204FC9F945685B7EFA@MW4PR02MB7428.namprd02.prod.outlook.com>
Content-Type: text/plain; charset="UTF-8"; format="flowed"
Content-Transfer-Encoding: 7bit
X-ClientProxiedBy: TY2PR02CA0065.apcprd02.prod.outlook.com (2603:1096:404:e2::29) To TYAPR01MB5689.jpnprd01.prod.outlook.com (2603:1096:404:8053::7)
MIME-Version: 1.0
X-MS-PublicTrafficType: Email
X-MS-TrafficTypeDiagnostic: TYAPR01MB5689:EE_|TYWPR01MB9510:EE_
X-MS-Office365-Filtering-Correlation-Id: ad9e01d1-a19f-420c-ac2e-08dbb2832c1f
X-MS-Exchange-SenderADCheck: 1
X-MS-Exchange-AntiSpam-Relay: 0
X-Microsoft-Antispam: BCL:0;
X-Microsoft-Antispam-Message-Info: 6fAGVaKOJMD+tMaYtw6ctaoQ+QjBkfw8Mpo+BANX1fJZGweQ4dX93N4Fr28vYHbdmTp56HAuUElaynDZUfN+el9QuxucUZoPoNkei4ICTcCCeJmrYosBDUzvA/tEVu1FoZK/+oA8bJQRAoFfc3H6RmbSluzlMV+QzD8fICnFiL3Onmt+Ycg8tyQO/d5Q4MxD0eHA1yN70T9+3ZAwXbdWzf7Ne4/qNq2Gqepj/3+oSYCQYecfFQHpS8SFwbdlTuDq9xLtJSVz8l6kPkyyaRDzTj+y4thtREz/gAeJ4UZP11bQ15tvoKWqN3cmurw6jZBAoJICxkGYP9x/30ykevDCJt6oxIM8Qdq1Z8l/+C4WHQ3XQJOLmIqZX5qk6ixSeClOvaAtU91X0F1sIa77FYlKA7E1pqOWbqWOWK8qJg3/SGF4wJ+5ThHZxq+ik3isjHwlAUD8Kw2dDIvcN4oTbrDruDJ1HxNUtC1WHaPC7N2QpsAkXmraNyW1GO1Oe46b0Yi+bb3eakedaLb/GGDT13ocWfP2oNQydt8b5buP8fy5j291f6U4uR2aWNZ1gr7GALXqyVJErU7u3iXwrKDgiroKLPJ4WiAMgQY8dFPFk9SKnxFM6jGTZHbVJxNog7DxQEnmz120QY7jp/PRMDWZP5w2J0MNFwTNHi7tJg+dIOsltUc=
X-Forefront-Antispam-Report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:TYAPR01MB5689.jpnprd01.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(136003)(366004)(396003)(346002)(376002)(39840400004)(186009)(1800799009)(451199024)(41300700001)(786003)(316002)(7416002)(26005)(31686004)(45080400002)(110136005)(478600001)(2906002)(8676002)(8936002)(66476007)(66556008)(66946007)(4326008)(54906003)(966005)(5660300002)(53546011)(52116002)(6486002)(36916002)(6506007)(6512007)(2616005)(83380400001)(38350700002)(38100700002)(41320700001)(31696002)(86362001)(43740500002)(45980500001); DIR:OUT; SFP:1102;
X-MS-Exchange-AntiSpam-MessageData-ChunkCount: 1
X-MS-Exchange-AntiSpam-MessageData-0: Btz2av8Zy5sA9ThfS4Uo4w44TMzdE4RNr7GJ5RptOM/dbWdXfDjwI/4eHAUT1MgOUDXvv622SIRWQdedOvcSvxE8XQVsMhYK2ERLU5VUe8PAjnLxpPWlsCtCGZIKxH4RNhY8aZRlkoyRQblMCzNcZrUj+oSkIPUJc8ljxZ0bonnr5Y7ecFWr9q0q4q/zYZug7xCEVondVP9Ow03yDEJDu8AEVCIQili0pmR1bYxiTzlKgCrZ8l0v84AuA8dxAQcZQm2zC4LWFXSSP2Wjh4RM86CxERu3PH6jmBstk9BCSVTc3Qy9Y4Y1Nit0AxIpWu9bW2OtNmVJ/Rpt35LYn3wmfRrOqCKRX0ZsIMUtvw8cVKYzb/Rg3G+N53dPPHsjG7kKpUQtDBhzN19YCqQnkl4uMhVnzPFx046Kx/HUrdkTT1kIX5UJJRk+ct2nhI3o/P7Q28aNaFax0xsdaA4vofV6wwY26Xl3JAPcUhhDfrVc3iBuOKG1Ocf7q8nH4UYtx7oBu86kbWPUNdmCpVxKC0yt4tcYcHmk/WKueGh/3ST0/yA2aWTTgTGk9JRwd+cnRE04KXTcC0f0dPAe2APzpCcVw50lQp9IKANARnuCZPV8hIjq0q8jLn4pGjr8TT0LPrv5GtEezSYcIS7hjXVFkJ/LeSOBdKeAkwvwNotZ3hFlLVxPYhepbPGs7c8xVL/WAE6Yq+jLz+SrYIG4O6I9NanChKBLK1ekG/jWwlECWxjAr3qMOpuPNGkv6hSBPkh5qScGYugXuJr1GkNcmO25/VQFgST7qj9wzFIkpKoRfbYKiJAWP9v8RE7aTEvPQsXILgrDlD5HAHXIsw3BDnYAjU78BHcgyLUZrgiWLgoP2l+in76JBwWhSHT1RRNpMkoPVbHGA4Y7Y5F+zrp+polfBjeGeE/8687F8kVujRO7kTZzZiqggVwFGccZKQSb3qgR7dF+IcvfpHwaKho4gL7smzuk3ncXJuwxm0eVL4L9i+iTl45qJPnS86ztvwG73NLp3Wbc2DRpwdEYOgdUMvyirNdSOTbSs7g+VuM2YMGXU6YxWTuZQ9WdyobQebDkROuRqyeRIiLQM+Oy01eFFYFEjk4s7vV5xCFWNeuBZB9kOj+rl96msKriKzwFt7Siusyx+bMG8JfMRiAR4BjOlbXL4N0yDZULx7Yu6RKiDdjMMcLDnxurzEFj7O+Yv2z/ZBzvLmAc3apXWbSKemKIKhGvxs77ZdQrsNcCRJ8DDiPv1GiZVsaLJy4Asuh5ECsdJ8DoHN4ptcdgBwgFVpry6RbQlrfb+G2VUhHjriIrxCrURztVqJKqIUwH2lK9sjvcpLRO+K3U6EgkA6bP3+kKoQwagkRhi0P/q/nUu7ddSI+JoVmpFUY1qMkoEnbJ0Q15m5FSN7zxzaMBqQ48hq6r1iRlYp4F6h+DStADaCsi0qs0yaz/OO+1sKx24vIoSg9FbypEVV961TQVKxL789xwZr0xlFy2DApWtdaoydErE+jdXKClRZtds7eFkqOZJ59+mQKLQWhRq0j5fjJmgz77v6d3SeXwFhJcftNDSim9I2Ka6JhGsuCCY85xtgQem93wLNpEpRXj
X-OriginatorOrg: it.aoyama.ac.jp
X-MS-Exchange-CrossTenant-Network-Message-Id: ad9e01d1-a19f-420c-ac2e-08dbb2832c1f
X-MS-Exchange-CrossTenant-AuthSource: TYAPR01MB5689.jpnprd01.prod.outlook.com
X-MS-Exchange-CrossTenant-AuthAs: Internal
X-MS-Exchange-CrossTenant-OriginalArrivalTime: 11 Sep 2023 04:54:25.5407 (UTC)
X-MS-Exchange-CrossTenant-FromEntityHeader: Hosted
X-MS-Exchange-CrossTenant-Id: e02030e7-4d45-463e-a968-0290e738c18e
X-MS-Exchange-CrossTenant-MailboxType: HOSTED
X-MS-Exchange-CrossTenant-UserPrincipalName: EvtsgfDDFd1vchN9BHXV+qULZsrkCOT44dMSKxWfsMyk8mDdFX1pnts/uJuXORobbSNqayQXdZ2QMKiqOPB6Kw==
X-MS-Exchange-Transport-CrossTenantHeadersStamped: TYWPR01MB9510
Archived-At: <https://mailarchive.ietf.org/arch/msg/multiformats/RWaTDiJfqCfC5tBZEwUOqeLEmNc>
Subject: Re: [Multiformats] Multiformats Considered Harmful
X-BeenThere: multiformats@ietf.org
X-Mailman-Version: 2.1.39
Precedence: list
List-Id: Discussion related to the various Multiformats data formats <multiformats.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/multiformats>, <mailto:multiformats-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/multiformats/>
List-Post: <mailto:multiformats@ietf.org>
List-Help: <mailto:multiformats-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/multiformats>, <mailto:multiformats-request@ietf.org?subject=subscribe>
X-List-Received-Date: Mon, 11 Sep 2023 04:54:32 -0000

On 2023-09-07 04:53, Michael Jones wrote:
> For the benefit of those added to the thread, you can read my original message that this is response to at https://self-issued.info/?p=2408.

Or a bit less pretty but as the actual email at
https://mailarchive.ietf.org/arch/msg/multiformats/KqdFPgjbUcYhc4dHoWqQrUFGi08
(thanks to the Archived-At header field).

Regards,   Martin.

> 
>                                                         -- Mike
> 
> From: Orie Steele <orie@transmute.industries>
> Sent: Wednesday, September 6, 2023 12:47 PM
> To: Carsten Bormann <cabo@tzi.org>
> Cc: Michael Jones <michael_b_jones@hotmail.com>; multiformats@ietf.org; Murray Kucherawy <superuser@gmail.com>; Barry Leiba <barryleiba@computer.org>; Francesca Palombini <francesca.palombini@ericsson.com>; Roman Danyliw <rdd@cert.org>; Paul Wouters <paul.wouters@aiven.io>; Russ Housley <housley@vigilsec.com>; Henk Birkholz <henk.birkholz@sit.fraunhofer.de>; Richard Barnes <rlb@ipv.sx>
> Subject: Re: [Multiformats] Multiformats Considered Harmful
> 
> I'll comment in the context of the experience working with multicodec and multibase at W3C.
> 
> And include a few folks I spoke with regarding this topic at the last IETF.
> 
> We implemented support for publicKeyMultibase, and helped register the NIST curves in order to be able to do "key translation" required to use Decentralized Identifiers or Verifiable Credentials.
> 
> https://github.com/multiformats/multicodec/pull/190
> 
> We've also used multibase encoded "proofValue" in JSON-LD / RDF to encode various kinds of Data Integrity Proofs:
> 
> https://github.com/w3c/vc-data-integrity
> 
> The 2 primary points of connection to W3C for this work are "encoding key representations" and "encoding signature / proof values"... not just encoding hashes as strings, although that is also commented on https://github.com/search?q=repo%3Aw3c%2Fvc-data-integrity%20digestMultibase&type=code ...
> 
> I'd add that digestMultibase is positioned as competing with digestSRI, and the W3C working group has no consensus on if it's worth not being compatible with SRI... In very much the same way the working group can't agree to recommend using publicKeyMultibase over publicKeyJwk... It's possible that might change in the current verifiable credentials working group, if it does not, that would also prove my general point regarding helpfulness.

<snip>